The product does not properly encode or decode the data, resulting in unexpected values.
Volume of CVEs assigned to CWE-172 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10160CRITICAL A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 throug | Jun 7, 2019 | 9.8 | 33 | NO | NO |
CVE-2018-3777CRITICAL Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests. | Aug 3, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-48784MEDIUM Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr | Jul 14, 2026 | 6.1 | 28 | NO | NO |
CVE-2025-12758HIGH Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take | Nov 27, 2025 | 7.5 | 28 | NO | NO |
CVE-2026-42926MEDIUM When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and p | May 13, 2026 | 5.8 | 26 | NO | NO |
CVE-2025-27110HIGH Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional | Feb 25, 2025 | 7.5 | 24 | NO | NO |
CVE-2016-6691CRITICAL service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework cr | Oct 10, 2016 | 9.8 | 24 | NO | NO |
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user | Feb 21, 2018 | 3.3 | 23 | NO | YES |
CVE-2019-12677MEDIUM A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of | Oct 2, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-7173MEDIUM A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. | Feb 15, 2018 | 5.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.